NEW
Font size
WorksheetsNDC + CA Quiz
Total questions: 40
Worksheet time: 20mins
The primary objective of Information Security is to protect information with respect to:
Cost reduction
Performance optimization
Confidentiality, Integrity, and Availability
Network scalability
A vulnerability is best defined as:
A method used by attackers
A weakness that can be exploited
An incident causing damage
A security policy violation
Which firewall implementation places a bastion host behind a packet-filtering router?
Dual-homed firewall
Screened subnet firewall
Screened host firewall
Proxy firewall
Stateful inspection firewalls differ from packet filtering firewalls because they:
Work only at application layer
Maintain session state information
Do not inspect packet headers
Are stateless by design
iptables primarily operates at which layer of the OSI model?
Physical
Data Link
Network
Application
Wireshark is mainly used for:
Firewall rule enforcement
Packet capture and analysis
Malware removal
VPN tunneling
Which component of a firewall architecture isolates public-facing services?
LAN
Core switch
DMZ
Internal VLAN
IDS differs from IPS because IDS primarily:
Blocks traffic automatically
Modifies packets
Detects and alerts
Encrypts sessions
A host-based IDS (HIDS) mainly monitors:
Network traffic patterns
Router logs
System-level activities
External threats only
Defense-in-depth refers to:
Single strong perimeter firewall
Multiple layered security controls
Encryption-only strategy
Cloud-based defense model
(Scenario) During a lab, iptables rules are not working as expected after reboot. What is the most likely cause?
Kernel modules not loaded
Rules not saved persistently
Incorrect default policy
Wrong network interface
(Scenario) An organization observes slow network performance after enabling deep packet inspection on its firewall. What is the most appropriate next step?
Disable all firewall rules
Tune inspection policies
Remove IDS
Switch to packet filtering only
(Scenario) While analyzing packets in Wireshark, repeated SYN packets without ACKs are observed. This most likely indicates:
Port scanning
SYN flood attack
DNS poisoning
ARP spoofing
(Scenario) A security team wants to prevent brute-force SSH attacks using iptables. Which approach is most suitable?
Static ACCEPT rules
Packet mirroring
Rate limiting with DROP targets
Disabling SSH permanently
(Scenario) Snort generates alerts but traffic is not blocked. What configuration change is required?
Enable promiscuous mode
Deploy Snort inline as IPS
Change rule syntax
Increase log storage
(Scenario) During VPN setup, split tunneling is enabled. What is the primary risk?
Increased latency
Data leakage through local network
Certificate expiration
Tunnel failure
(Scenario) A DoS attack is detected during lab simulation. Which mitigation is most effective at firewall level?
Enable logging only
Increase bandwidth
Rate limiting and IP blacklisting
Disable IDS
Which VPN protocol operates at Layer 3 and supports encryption and authentication?
PPTP
L2TP
IPsec
GRE
SIEM systems primarily perform:
Packet filtering
Log correlation and event triggering
Malware detection only
Vulnerability scanning
IDS sensors deployed close to hosts are referred to as:
Network sensors
Distributed sensors
Host-based sensors
Perimeter sensors
The primary purpose of a security audit is to:
Eliminate all risks
Measure compliance and control effectiveness
Replace management
Install security tools
Internal audit teams must primarily ensure:
Legal prosecution
Independent assessment
System development
Vendor management
The principle of audits that requires evidence-based conclusions is known as:
Confidentiality
Due professional care
Availability
Risk acceptance
Assurance evaluation levels generally indicate:
Risk severity
Depth of evaluation
Compliance cost
Auditor experience
NIST Cybersecurity Framework is organized around:
Domains
Control objectives
Core functions
Audit reports
GDPR primarily protects:
Financial data only
Personal data of individuals
Corporate trade secrets
Network logs
ISO/IEC 27001 focuses mainly on:
Product quality
Information Security Management System (ISMS)
Software development lifecycle
Network monitoring
SOC reports are issued to evaluate:
Software vulnerabilities
Internal controls of service organizations
Network performance
Incident response speed
COBIT is best described as a framework for:
Network defense
IT governance and management
Penetration testing
Cryptographic design
Compared to ITIL, COBIT focuses more on:
Service operation
Governance and control objectives
Incident handling
Change tickets
HIPAA primarily applies to:
Financial institutions
Healthcare information
Telecom providers
Educational records
PCI DSS compliance levels are determined based on:
Type of card used
Number of transactions processed
Geographic region
Encryption algorithms
CIS Critical Security Controls are best described as:
Legal mandates
Prioritized best practices
Penetration testing tools
Vendor-specific rules
CIS Benchmarks mainly provide:
Risk scores
Secure configuration guidelines
Audit checklists
Incident reports
SSE-CMM primarily addresses:
Network throughput
Security engineering maturity
Legal compliance
Incident response
(Scenario) During a GDPR audit, personal data is found stored without consent records. What is the immediate compliance gap?
Data minimization
Lawful basis for processing
Data portability
Breach notification
(Scenario) An ISO 27001 audit identifies missing risk assessment documentation. Which clause area is most affected?
Asset management
Risk management process
Incident handling
Supplier relations
(Scenario) A global bank’s internal audit finds weak segregation of duties in IT operations. This primarily violates:
Availability principle
Internal control effectiveness
Data encryption policy
Network zoning
(Scenario) An organization handling card payments stores CVV numbers post-authorization. Which standard is violated?
HIPAA
GDPR
PCI DSS
SOX
(Scenario) During a SOX compliance audit, lack of logging for financial systems is observed. What is the most critical impact?
Reduced system performance
Inability to ensure audit trail
Increased storage cost
Delayed transactions
